Delete win_cmd_rar.yml

redundant with  ./rules/windows/process_creation/win_data_compressed_with_rar.yml
authorship was updated
This commit is contained in:
yugoslavskiy 2019-11-11 01:58:22 +03:00 committed by GitHub
parent afb17d0e0e
commit 521d9311c7
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -1,21 +0,0 @@
title: Command-Line Creation of a RAR file
description: Detect compression of data into a RAR file using the rar.exe utility.
status: experimental
author: E.M. Anhaus (orignally from Atomic Blue Detections, Endgame)
date: 2019/10/24
tags:
- attack.exfiltration
- attack.t1002
detection:
selection:
Image:
- '*rar.exe'
CommandLine:
- '* a *'
condition: selection
falsepositives:
- legit creation of a rar file using cmd
level: high
logsource:
category: process_creation
product: windows